¦b¨å«¬ªº®Õ¶éºôÀô¹Ò¤¤¡A¸ô¥Ñ¾¹¤@¯ë³B©ó¨¾¤õÀ𪺥~³¡¡A­t³d»PInternetªº³s±µ¡C³oºØ©Ý¥·µ²ºc¹ê»Ú¤W¬O±N¸ô¥Ñ¾¹¼ÉÅS¦b®Õ¶éºô
¦w¥þ¨¾½u¤§¥~¡A¦pªG¸ô¥Ñ¾¹¥»¨­¤S¥¼±Ä¨ú¾A·íªº¦w¥þ¨¾½dµ¦²¤¡A´N¥i¯à¦¨¬°§ðÀ»ªÌµo°_§ðÀ»ªº¤@¶ô¸õªO¡A¹ï¤º³¡ºô¸ô¦w¥þ³y¦¨
«Â¯Ù¡C 

¥»¤å¥HCisco 2621¸ô¥Ñ¾¹¬°¨Ò¡A¸Ô²Ó¤¶²Ð±N¤@¥x¸ô¥Ñ¾¹°t¸m¬°³ùÂS¸ô¥Ñ¾¹ªº¹ê²{¤èªk¡A¨Ï¤§¦¨¬°®Õ¶éºô©è±s¥~³¡§ðÀ»ªº²Ä¤@¹D
¦w¥þ¿Ã«Ì»Ù¡C 

¤@¡B¾A¥Î©ó³X°Ýªíªº¦w¥þ¨¾½dµ¦²¤ 

1. ¨¾¤î¥~³¡IP¦a§}´ÛÄF 

¥~³¡ºô¸ôªº¨Ï¥ÎªÌ¥i¯à·|¨Ï¥Î¤º³¡ºôªº¦XªkIP¦ì§}©ÎªÌ´`Àô¦ì§}§@¬°¨Ó·½¦ì¸m¡A±q¦Ó¹ê²{«Dªk³X°Ý¡C°w¹ï¦¹Ãþ°ÝÃD¥i«Ø¥ß¦p¤U
³X°Ý¦Cªí¡G 

access-list 101 deny ip 10.0.0.0 0.255.255.255 any 

access-list 101 deny ip 192.168.0.0 0.0.255.255 any 

access-list 101 deny ip 172.16.0.0 0.0.255.255 any 

! ªý¤î¨Ó·½¦ì¸m¬°¨p¦³¦a§}ªº©Ò¦³³q«H¬y¡C 

access-list 101 deny ip 127.0.0.0 0.255.255.255 any 

! ªý¤î¨Ó·½¦ì¸m¬°¦^Àô¦a§}ªº©Ò¦³³q«H¬y¡C 

access-list 101 deny ip 224.0.0.0 7.255.255.255 any 

! ªý¤î¨Ó·½¦ì¸m¬°¦h¥Øªº¦ì§}ªº©Ò¦³³q«H¬y¡C 

access-list 101 deny ip host 0.0.0.0 any 

! ªý¤î¨S¦³¦C¥X¨Ó·½¦ì¸mªº³q«H¬y¡C 

ª`¡G¥i¥H¦b¥~³¡³s±µªº¦V¤º¤è¦V¨Ï¥Î101¹LÂo¡C 

2. ¨¾¤î¥~³¡ªº«Dªk±´´ú 

«Dªk³X°ÝªÌ¹ï¤º³¡ºô¸ôµo°_§ðÀ»«e¡A©¹©¹·|¥Îping©Î¨ä¥L©R¥O±´´úºô¸ô¡A©Ò¥H¥i¥H³z¹L¸T¤î±q¥~³¡¥Îping¡Btracerouteµ¥±´´úºô
¸ô¨Ó¶i¦æ¨¾½d¡C¥i«Ø¥ß¦p¤U³X°Ý¦Cªí: 

access-list 102 deny icmp any any echo 

! ªý¤î¥Îping±´´úºô¸ô¡C 

access-list 102 deny icmp any any time-exceeded 

! ªý¤î¥Îtraceroute±´´úºô¸ô¡C 

ª`¡G¥i¦b¥~³¡³s±µªº¦V¥~¤è¦V¨Ï¥Î102¹LÂo¡C¦b³o¸Ì¥D­n¬Oªý¤îµª´_¿é¥X¡A¤£ªý¤î±´´ú¶i¤J¡C 

3. «OÅ@¸ô¥Ñ¾¹¤£¨ü§ðÀ» 

¸ô¥Ñ¾¹¤@¯ë¥i¥H³z¹Ltelnet©ÎSNMP³X°Ý¡AÀ³¸Ó½T«OInternet¤W¨S¦³¤H¯à¥Î³o¨Ç¨óij§ðÀ»¸ô¥Ñ¾¹¡C°²©w¸ô¥Ñ¾¹¥~³¡³s±µserial0ªºIP¬°
200.200.200.1¡A¤º³¡³s±µfastethernet0ªºIP¬°200.200.100.1¡C¥i¥H¥Í¦¨ªý¤îtelnet¡BSNMPªA°Èªº¦V¤º¹LÂo«OÅ@¸ô¥Ñ¾¹¡C«Ø¥ß¦p¤U¦C
ªí¡G 

access-list 101 deny tcp any 200.200.200.1 0.0.0.0 eq 23 

access-list 101 deny tcp any 200.200.100.1 0.0.0.0 eq 23 

access-list 101 deny udp any 200.200.200.1 0.0.0.0 eq 161 

access-list 101 deny udp any 200.200.100.1 0.0.0.0 eq 161 

ª`: ¦b¥~³¡³s±µªº¦V¤º¤è¦V¨Ï¥Î101¹LÂo¡C·íµM³o·|¹ïºÞ²z­ûªº¨Ï¥Î³y¦¨¤@©wªº¤£«K¡A³o´N»Ý­n¦b¤è«K»P¦w¥þ¤§¶¡°µ¥X¿ï¾Ü¡C 

4. ªý¤î¹ïÃöÁä³s±µ°ðªº«Dªk³X°Ý 

ÃöÁä³s±µ°ð¥i¯à¬O¤º³¡¨t²Î¨Ï¥Îªº³s±µ°ð©ÎªÌ¬O¨¾¤õÀ𥻨­¼ÉÅSªº³s±µ°ð¡C¹ï³o¨Ç³s±µ°ðªº³X°ÝÀ³¸Ó¥[¥H­­¨î¡A§_«h³o¨Ç³]³Æ
´N«Ü®e©ö¨ü¨ì§ðÀ»¡C«Ø¥ß¦p¤U³X°Ý¦Cªí¡G 

access-list 101 deny tcp any any eq 135 

access-list 101 deny tcp any any eq 137 

access-list 101 deny tcp any any eq 138 

access-list 101 deny tcp any any eq 139 

access-list 101 deny udp any any eq 135 

access-list 101 deny udp any any eq 137 

access-list 101 deny udp any any eq 138 

access-list 101 deny udp any any eq 139 

5. ¹ï¤º³¡ºô¸ôªº­«­n¦øªA¾¹¶i¦æ­­¨î 

¹ï©ó¨S¦³°t³Æ±M¥Î¨¾¤õÀ𪺮նéºô¸ô¡A±Ä¥Î°ÊºA¤À²Õ¹LÂo§Þ³N«Ø¥ß¹ï­«­n¦øªA¾¹ªº³X°Ý­­¨î´NÅã±o¤×¬°­«­n¡C¹ï©ó°t³Æ¤F±M¥Î
¨¾¤õÀ𪺮նéºô¸ô¡A¦¹¶µ¥ô°È¥i¥H¦b¨¾¤õÀð¤W§¹¦¨¡A³o¼Ë¥i¥H´î»´¸ô¥Ñ¾¹ªº­t¾á¡CµL½×¬O¾A¥Î©ó¸ô¥Ñ¾¹¹ê²{¡AÁÙ¬O¦b¨¾¤õÀð¤W
§¹¦¨³]¸m¡A­º¥ý³£À³¸Ó¨î©w¤@®M³X°Ý³W«h¡C¥i¥H¦Ò¼{«Ø¥ß¦p¤Uªº³X°Ý³W«h: 

¡´ ¤¹³\¥~³¡¨Ï¥ÎªÌ¨ìWeb¦øªA¾¹ªº¦V¤º³s±µ½Ð¨D¡C 

¡´ ¤¹³\Web¦øªA¾¹¨ì¥~³¡¨Ï¥ÎªÌªº¦V¥~µª´_¡C 

¡´ ¤¹³\¥~³¡SMTP¦øªA¾¹¦V¤º³¡«H¥ó¦øªA¾¹ªº¦V¤º³s±µ½Ð¨D¡C 

¡´ ¤¹³\¤º³¡«H¥ó¦øªA¾¹¦V¥~³¡SMTP¦øªA¾¹ªº¦V¥~µª´_¡C 

¡´ ¤¹³\¤º³¡«H¥ó¦øªA¾¹¦V¥~DNS¬d¸ß¡C 

¡´ ¤¹³\¨ì¤º³¡«H¥ó¦øªA¾¹ªº¦V¤ºªºDNSµª´_¡C 

¡´ ¤¹³\¤º³¡¥D¹q¸£ªº¦V¥~TCP³s±µ¡C 

¡´ ¤¹³\¹ï½Ð¨D¥D¹q¸£ªº¦V¤ºTCPµª´_¡C 

¨ä¥L³X°Ý³W«h¥i¥H®Ú¾Ú¦U¦Ûªº¹ê»Ú±¡ªp«Ø¥ß¡C¦C¥X¤¹³\ªº©Ò¦³³q«H¬y«á¡A³]­p³X°Ý¦Cªí´NÅܱo²³æ¤F¡Cª`·NÀ³±N©Ò¦³¦V¤º¹ï¸Ü
À³¥Î©ó¸ô¥Ñ¾¹¥~³¡³s±µªºIN¤è¦V¡A©Ò¦³¦V¥~¹ï¸ÜÀ³¥Î©ó¸ô¥Ñ¾¹¥~³¡³s±µªºOUT¤è¦V¡C 

¤G¡B±`¨£§ðÀ»¤â¬q¤Î¨ä¹ïµ¦ 

1. ¨¾¤î¥~³¡ICMP­«©w¦V´ÛÄF 

§ðÀ»ªÌ¦³®É·|§Q¥ÎICMP­«©w¦V¨Ó¹ï¸ô¥Ñ¾¹¶i¦æ­«©w¦V¡A±N¥»À³°e¨ì¥¿½T¥Ø¼Ðªº¸ê°T­«©w¦V¨ì¥¦­Ì«ü©wªº³]³Æ¡A±q¦ÓÀò±o¦³¥Î
¸ê°T¡C¸T¤î¥~³¡¨Ï¥ÎªÌ¨Ï¥ÎICMP­«©w¦Vªº©R¥O¦p¤U¡G 

interface serial0 

no ip redirects 

2. ¨¾¤î¥~³¡·½¸ô¥Ñ´ÛÄF 

·½¸ô¥Ñ¿ï¾Ü¬O«ü¨Ï¥Î¸ê®ÆÃì¸ô¼h¸ê°T¨Ó¬°¸ê®Æ³ø¶i¦æ¸ô¥Ñ¿ï¾Ü¡C¸Ó§Þ³N¸ó¶V¤Fºô¸ô¼hªº¸ô¥Ñ¸ê°T¡A¨Ï¤J«IªÌ¥i¥H¬°¤º³¡ºôªº¸ê
®Æ³ø«ü©w¤@­Ó«Dªkªº¸ô¥Ñ¡A³o¼Ë­ì¥»À³¸Ó°e¨ì¦Xªk¥Øªº¦aªº¸ê®Æ³ø´N·|³Q°e¨ì¤J«IªÌ«ü©wªº¦a§}¡C¸T¤î¨Ï¥Î·½¸ô¥Ñªº©R¥O¦p
¤U¡G 

no ip source-route 

3. ¨¾¤îµs¥Î¤º³¡IP¦a§} 

§ðÀ»ªÌ¥i¯à·|µs¥Î¤º³¡IP¦a§}¶i¦æ«Dªk³X°Ý¡C°w¹ï³o¤@°ÝÃD¡A¥i¥H§Q¥ÎCisco¸ô¥Ñ¾¹ªºARP©R¥O±N©T©wIP¦a§}¸j©w¨ì¬Y¤@MAC¦a
§}¤§¤W¡C¨ãÅé©R¥O¦p¤U¡G 

arp ©T©wIP¦a§} MAC¦a§} arpa 

4. ¦b·½¯¸¥x¨¾¤îsmurf 

­n¦b·½¯¸¥x¨¾¤îsmurf¡AÃöÁä¬Oªý¤î©Ò¦³ªº¦V¤º¦^Åã½Ð¨D¡C³o´N­n¨¾¤î¸ô¥Ñ¾¹±N«ü¦Vºô¸ô¼s¼½¦a§}ªº³q«H¬M®g¨ì°Ï°ìºô¸ô¼s¼½¦a
§}¡C¥i¥H¦bLAN³s±µ¤è¦¡¤¤¿é¤J¦p¤U©R¥O¡G 

no ip directed-broadcast 

¤T¡BÃö³¬¸ô¥Ñ¾¹¤W¤£¥ÎªºªA°È 

¸ô¥Ñ¾¹°£¤F¥i¥H´£¨Ñ¸ô®|¿ï¾Ü¥~¡A¥¦ÁÙ¬O¤@¥x¦øªA¾¹¡A¥i¥H´£¨Ñ¤@¨Ç¦³¥ÎªºªA°È¡C¸ô¥Ñ¾¹°õ¦æªº³o¨ÇªA°È¥i¯à·|¦¨¬°¼Ä¤H§ðÀ»
ªº¬ð¯}¤f¡A¬°¤F¦w¥þ°_¨£¡A³Ì¦nÃö³¬³o¨ÇªA°È¡C 

³z¹L¥H¤W¤¶²Ðªº¦UºØ¤èªk¡A§Ú­Ì¦¨¥\¦a±N¤@¥x´¶³q¸ô¥Ñ¾¹°t¸m¬°¤@¥x³ùÂS¸ô¥Ñ¾¹¡A¦b¨S¦³¼W¥[¥ô¦ó§ë¤Jªº±¡ªp¤U¡A´£°ª¤F¾ã­Ó
¶é°Ïºôªº¦w¥þ©Ê¡C¦ýÀ³¸Ó»¡©úªº¬O¡A³ùÂS¸ô¥Ñ¾¹ªº¹ê²{¬O¥HÄ묹¾ã­Óºô¸ôªº®Ä²v¬°¥N»ùªº¡A¥i¯à·|¼vÅT¨ì¶é°Ïºô¹ï¥~³X°Ýªº³t
«×¡C